Skip to content

ace-core v0.3.0 — Governed cognition

Choose a tag to compare

@eamirian eamirian released this 05 Aug 15:11
· 141 commits to main since this release
6738708

ace-core v0.3.0

This release ships the E1 governed-cognition boundary: a canonical teach → propose → inspect → approve → use → measure → revise/retire lifecycle, bounded extension negotiation, immutable governance history, product-scoped selection/use evidence, schemas v169–v171, compatibility adapters, and optional/naked-kernel operation.

Immutable release and publication binding

  • Tag: v0.3.0
  • Merge commit: 673870817a0d4a5e05af7f4149330acbb1012c80
  • Reviewed candidate commit: c56a5b2f8291faca557d1b345b51574911375d62
  • Merge and candidate Git trees: 3ee0ec3fa6c88ecd9f932d08788f7c54d9dd730e (identical)
  • Exact release-commit package-matrix receipt SHA-256: 1a1a2efa46eaf57ac3f36ce51b1eadb1843f692f4e9a842051a48afccfac7775
  • Trusted publication workflow: passed
  • PyPI project
  • Wheel SHA-256: c60e49c97a5e5cb4eb8615f03720d88b1c2020f67f4d5ef9f9dffbd8ad2d1dbd
  • Source-distribution SHA-256: a9ab2a589adb983a85dc81c154c73aba79c0ecaba0985697547d518e9385c1c6
  • Final machine-readable publication receipt, file SHA-256 68dad95a6344cd7c763644282eb0cb4910093b9d68eb33cef1bb6e69fbbf02c2

Both PyPI hashes exactly equal the corresponding artifacts produced by the full matrix at the immutable tagged commit. A clean environment installed ace-core==0.3.0 from the public index and verified package/thin-client identity 0.3.0, schema head 171, all eleven MCP tools, and naked extension loading.

The pre-merge candidate used a different commit timestamp, so its archive hashes differed. Registry verification caught this. The complete matrix was rerun from the tagged release commit, and a member-by-member comparison proved identical payloads (1,235 wheel members; 1,339 source-distribution members); only archive timestamps changed. See the publication review addendum.

Security decision

The owner-directed author review accepted all 14 required boundaries after eight remediations, with no unresolved critical/high finding inside the documented trusted-package boundary. This is not independent certification. Reviewer independence was explicitly waived by the release owner for v0.3.0 only.

Post-publication independent AI review and formal E1 closeout

After publication, a fresh Anthropic Claude Fable 5 invocation independently reviewed the frozen 51-file surface and exact release receipts with read-only tools, no session persistence, no author-review record, and no web or command execution. It accepted all 14 required boundaries with zero critical, high, or medium finding.

The earlier owner waiver and author review above remain part of the historical release record, but are superseded for the E1 gate by this independent AI review and countersignature. This is independent AI source-review assurance—not a human penetration test, professional audit, or certification. The five low and two informational findings are accepted only within their documented containment and deadlines; a changed artifact, widened trust boundary, failed containment, or expired residual without review reopens the relevant gate.

Deployment inventory

The sole configured/running upgraded deployment discovered by the operator, local-compose-infra-surrealdb-1, is at schema 171. Dry-run and persisted/read-verified inventories agree on 1,151/1,151 rows and receipt-set SHA-256 ba6a2b0f231beca56ac95b9f221681fb739d558be0a9fa50a5484feef9b87f36. The retained receipts are attached to PR #44. No legacy history was deleted.

Verification

All final-commit GitHub checks passed: full tests, naked kernel, security audit, lint, canvas typecheck/tests/build, and container build. The clean local gates and deterministic current/N-1/mixed-package matrix also passed.